Monday, May 24, 2021

L2TP over NAT through a Sonicwall, error 789

Trying to establish a L2TP connection from outside the network to a Win2012r2 RRAS server.

I have all the NAT rules set up on the firewall. I can see the packets flowing through the Sonicwall and also the certificate request/reply occurs over port 500 when I run wireshark on the host that I'm trying to connect with.

The connection then fails with error 789 on the host. I also don't see any logs on my RADIUS server that there was ever a connection attempt.

Alternately, when I'm inside the network the RRAS server picks up and connects fine, and the RADIUS server log shows the connection approval.

I found a forum post on Spiceworks which mentioned making a REG DWORD "AssumeUDPEncapsulationContextOnSendRule" registry entry and set it to "2" to no avail.

I must be missing a detail somewhere along the way that would have this working but am not certain what it is.

TIA!



No comments:

Post a Comment